# Problem configuring TLS WS

**URL:** <https://community.hivemq.com/t/problem-configuring-tls-ws/1601>\
**Category:** HiveMQ Community Edition\
**Created:** [November 16, 2022, 6:56pm UTC](https://community.hivemq.com/t/problem-configuring-tls-ws/1601 "2022-11-16T18:56:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aim4apex](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.hivemq.com/aim4apex/32/467_2.png) [@aim4apex](https://community.hivemq.com/u/aim4apex)\
**Post date:** [November 16, 2022, 6:56pm UTC](https://community.hivemq.com/t/problem-configuring-tls-ws/1601/1 "2022-11-16T18:56:02Z")

</div>

I would like to request help diagnosing a problem configuring TLS Websockets for a MQTT broker.

I created the keystore using this script and certs provided by CA for [mqtt.hostname.com](http://mqtt.hostname.com) domain:

```auto
    brokerKeystoreName="hivemq"
    brokerKeystorePass="--redacted--"
    brokerCertName="mqtt_hostname_com/mqtt_hostname_com"
    rootCACertName="mqtt_hostname_com/DigiCertCA"

    #import broker cert.
    printf "yes\n" |keytool -import -file ${brokerCertName}.crt -alias "hivemq" \
      -keystore ${brokerKeystoreName}.jks -storepass $brokerKeystorePass

    #import root CA cert.
    printf "yes\n" |keytool -import -file ${rootCACertName}.crt -alias "digicert" \
      -keystore ${brokerKeystoreName}.jks -storepass $brokerKeystorePass

```

When I try to activate in the HiveMQ config file I get this error:  
ERROR - Could not read the configuration file /opt/hivemq/conf/config.xml. Using default config

Here’s the config snippet

```auto
        <tls-websocket-listener>
            <port>443</port>
            <bind-address>0.0.0.0</bind-address>
            <path>/mqtt</path>
            <subprotocols>
                <subprotocol>mqttv3.1</subprotocol>
                <subprotocol>mqtt</subprotocol>
            </subprotocols>
            <allow-extensions>true</allow-extensions>
            <proxy-protocol>true</proxy-protocol>
            <tls>
                <client-authentication-mode>NONE</client-authentication-mode>
                <truststore>
                    <path>/opt/hivemq/conf/broker-truststore.jks</path>
                    <password>--redacted--</password>
                </truststore>
            </tls>
        </tls-websocket-listener>

```

If I remove the tls-websocket-listener element the rest of config.xml works as expected. Is the problem related to the truststore?

---

<div class="post-metadata">

**Author:** ![michael\_w](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.hivemq.com/michael_w/32/200_2.png) [@michael\_w](https://community.hivemq.com/u/michael_w)\
**Post date:** [November 16, 2022, 9:39pm UTC](https://community.hivemq.com/t/problem-configuring-tls-ws/1601/2 "2022-11-16T21:39:57Z")

</div>

Hi @aim4apex,

it seems you are using the wrong store tag, can you please rename truststore to keystore and try again and add the private-key-password as shown in example below.

You only need the truststore when you want to verify certs from clients but as you have  
client-authentication-mode set to NONE we don’t need this.

Keystore config example:

```auto
<keystore>
   <path>/path/to/the/key/store.jks</path>
   <password>password-keystore</password>
   <private-key-password>password-key</private-key-password>
</keystore>

```

Greetings,  
Michael from the HiveMQ team

---

<div class="post-metadata">

**Author:** ![aim4apex](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.hivemq.com/aim4apex/32/467_2.png) [@aim4apex](https://community.hivemq.com/u/aim4apex)\
**Post date:** [November 16, 2022, 9:48pm UTC](https://community.hivemq.com/t/problem-configuring-tls-ws/1601/3 "2022-11-16T21:48:13Z")

</div>

Thank you for the helpful reply.
